| Control | HIPAA Reference | Description | Control Assessment | Explanation of Compliance | HIPAA Compliant |
| 1 | §164.308(a)(1)(i) | Implement policies and procedures to prevent, detect, contain, and correct security violations | Does your practice develop, document, and implement policies and procedures for assessing and managing risk to its electronic protected health information ePHI? |
| 2 | §164.308(a)(1)(ii)(B) | Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with Sec 164.206(a). | Does your practice have a formal documented program to mitigate the threats and vulnerabilities to ePHI identified through the risk analysis? |
| 3 | §164.308(a)(1)(ii)(D) | Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports. | Does your practice have policies and procedures for the review of information system activity? |
| 4 | §164.308(a)(3)(ii)(B) | Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate. | Do your practice’s policies and procedures require screening workforce members prior to enabling access to its facilities, information systems, and ePHI to verify that users are trustworthy? |
| 5 | §164.308(a)(3)(ii)(C) | Implement procedures for termination access to electronic protected health information when the employment of a workforce member ends or as required by determination made as specified in paragraph (a)(3)(ii)(B) of this section. | Does your practice have policies and procedures for terminating authorized access to its facilities, information systems, and ePHI once the need for access no longer exists? |
| 6 | §164.308(a)(3)(ii)(C) | Implement procedures for termination access to electronic protected health information when the employment of a workforce member ends or as required by determination made as specified in paragraph (a)(3)(ii)(B) of this section. | Does your practice have formal policies and procedures to support when a workforce member’s employment is terminated and/or a relationship with a business associate is terminated? |
| 7 | §164.308(a)(5)(i) | Implement a security awareness and training program for all members of its workforce (including management). | Does your practice provide ongoing basic security awareness to all workforce members, including physicians? |
| 8 | §164.308(a)(5)(i) | Implement a security awareness and training program for all members of its workforce (including management). | Does your practice keep records that detail when each workforce member satisfactorily completed periodic training? |
| 9 | §164.308(a)(5)(ii)(A) | (5)(i) Standard: Security awareness and training. Implement a security awareness and training program for all members of its workforce (including management).
(ii) Implementation specifications. Implement:
(A) Security reminders (Addressable). Periodic security updates. | As part of your practice’s ongoing security awareness activities, does your practice prepare and communicate periodic security reminders to communicate about new or important issues? |
| 10 | §164.308(a)(6)(i) | Implement policies and procedures to address security incidents. | Does your practice have policies and procedures designed to help prevent, detect and respond to security incidents? |
| 11 | §164.308(a)(7)(i) | Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information. | Does your practice know what critical services and ePHI it must have available to support decision making about a patient’s treatment during an emergency? |
| 12 | §164.308(a)(7)(ii)(E) | Assess the relative criticality of specific applications and data in support of other contingency plan components. | Does your practice implement procedures for identifying and assessing the criticality of its information system applications and the storage of data containing ePHI that would be accessed through the implementation of its contingency plans? |
| 13 | §164.316(b)(1)(i) | (b)(1) Standard: Documentation.
(i) Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form; and
(ii) If an action, activity or assessment is required by this subpart to be documented, maintain a written (which may be electronic) record of the action, activity, or assessment. | Does your practice assure that its policies and procedures are maintained in a manner consistent with other business records? |
| 14 | §164.316(b)(1)(ii) | (b)(1) Standard: Documentation.
(i) Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form; and
(ii) If an action, activity or assessment is required by this subpart to be documented, maintain a written (which may be electronic) record of the action, activity, or assessment. | Does your practice assure that its other security program documentation is maintained in written manuals or in electronic form? B) is the documentation easily accessible for employees? |
| 15 | §164.316(b)(2)(iii) | (b)(2) Implementation specifications:
(i) Time limit (Required). Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.
(ii) Availability (Required). Make documentation available to those persons responsible for implementing the procedures to which the documentation pertains.
(iii) Updates (Required). Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of the electronic protected health information.
| Does your practice assure that it periodically reviews and updates when needed its policies, procedures, and other security program documentation? |
| 16 | §164.312(a)(2)(i) | Assign a unique name and/or number for identifying and tracking user identity. | Does your practice have policies and procedures for the assignment of a unique identifier for each authorized user? |
| 17 | §164.312(a)(2)(i) | Assign a unique name and/or number for identifying and tracking user identity. | Does your practice require that each user enter a unique user identifier prior to obtaining access to ePHI? |
| 18 | §164.312(a)(2)(ii) | Establish (and implement as needed) procedures for obtaining necessary electronic protected health information during an emergency. | Does your practice back up ePHI by saving an exact copy to a magnetic disk/tape or a virtual storage, such as a cloud environment? |
| 19 | §164.312(a)(2)(ii) | Establish (and implement as needed) procedures for obtaining necessary electronic protected health information during an emergency. | Does your practice have back up information systems so that it can access ePHI in the event of an emergency or when your practice’s primary systems become unavailable? |
| 20 | §164.312(a)(2)(ii) | Establish (and implement as needed) procedures for obtaining necessary electronic protected health information during an emergency. | Does your practice have the capability to activate emergency access to its information systems in the event of a disaster? |
| 21 | §164.312(a)(2)(iii) | Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity. | Does your practice have policies and procedures that require an authorized user’s session to be automatically logged-off after a predetermined period of inactivity? |
| 22 | §164.312(a)(2)(iv) | Implement a mechanism to encrypt and decrypt electronic protected health information. | Does your practice know the encryption capabilities of its information systems and electronic devices? |
| 23 | §164.312(c)(1) | Implement policies and procedures to protect electronic protected health information from improper alteration or destruction. | Does your practice have policies and procedures for protecting ePHI from unauthorized modification or destruction? |
| 24 | §164.312(c)(2) | Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner. | Does your practice have mechanisms to corroborate that ePHI has not been altered, modified, or destroyed in an unauthorized manner? |
| 25 | §164.312(e)(2)(i) | Implement security measures to ensure that electronically transmitted electronic protected health information is not improperly modified without detection until disposed of. | Does your practice know what encryption capabilities are available to it for encrypting ePHI being transmitted from one point to another? |
| 26 | §164.502(i) | §164.502(i) Standard: Uses and disclosures consistent with notice: A covered entity that is required by §164.520 to have a notice may not use or disclose protected health information in a manner inconsistent with such notice. A covered entity that is required by §164.520(b)(1)(iii) to include a specific statement in its notice if it intends to engage in an activity listed in §164.520(b)(1)(iii)(A)-(C), may not use or disclose protected health information for such activities, unless the required statement is included in the notice.
| Are uses and disclosures made by the covered entity consistent with its notice of privacy practices? |
| 27 | §164.520(a)(1) & (b)(1) | "§164.520(a)(1) Right to notice. Except as provided by paragraph (a)(2) or (3) of this section, an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information.
§164.520(b)(1) Required elements. The covered entity must provide a notice that is written in plain language and that contains the elements required by this paragraph.
(i) Header. The notice must contain the following statement as a header or otherwise prominently displayed: ""THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY."" (ii) Uses and disclosures. (iii) Separate statements for certain uses or disclosures. (iv) Individual rights. (v) Covered entity's duties. (vi) Complaints. (vii) Contact. (viii) Effective date. | Does the covered entity have a notice of privacy practices? |
| 28 | §164.310(b) | Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access electronic protected health information. | Does your practice keep an inventory and a location record of all of its workstation devices? |
| 29 | §164.310(c) | Implement physical safeguards for all workstations that access electronic protected health information, to restrict access to authorized users. | Do you regularly review your workstations’ locations to see which areas are more vulnerable to unauthorized use, theft, or viewing of the data? |
| 30 | §164.530(j) | §164.530(j)(1) Standard: Documentation. A covered entity must: (i) Maintain the policies and procedures provided for in paragraph (i) of this section in written or electronic form; (ii) If a communication is required by this subpart to be in writing, maintain such writing, or an electronic copy, as documentation; and (iii) If an action, activity, or designation is required by this subpart to be documented, maintain a written or electronic record of such action, activity, or designation. (iv) Maintain documentation sufficient to meet its burden of proof under § 164.414(b).
(2) Implementation specification: Retention period. A covered entity must retain the documentation required by paragraph (j)(1) of this section for six years from the date of its creation or the date when it last was in effect, whichever is later.
| Does the entity maintain all required policies and procedures, written communication, and documentation in written or electronic form? |